Repository navigation
Embed reviewed threat-detect digests in compiled workflows - #61857
Conversation
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Installation failures can still invoke an unverified detector or silently omit the warn-mode failure conclusion.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Pins threat-detect releases and verifies downloaded binaries against compiler-controlled digests.
Changes:
- Adds v0.5.2 digest pins and HTTPS mirror configuration.
- Gates detector execution on installation success.
- Updates tests, documentation, generated locks, and release notes.
| File | Description |
|---|---|
pkg/constants/version_constants.go |
Defines reviewed release pins. |
pkg/constants/version_constants_test.go |
Validates the pin matrix. |
actions/setup/sh/install_threat_detect_binary.sh |
Verifies downloaded binaries. |
actions/setup/sh/install_threat_detect_binary_test.sh |
Tests installer failure modes. |
actions/setup/sh/conclude_threat_detection.sh |
Concludes detector execution. |
pkg/workflow/threat_detection_external.go |
Gates external detector execution. |
pkg/workflow/threat_detection_steps.go |
Emits installer arguments and pins. |
pkg/workflow/threat_detection_config.go |
Parses mirror configuration. |
pkg/workflow/*threat_detection*_test.go |
Covers compiler and conclusion behavior. |
pkg/parser/schemas/main_workflow_schema.json |
Validates HTTPS mirror URLs. |
pkg/parser/schema_threat_detection_test.go |
Tests mirror schema validation. |
docs/src/content/docs/reference/threat-detection.md |
Documents mirrors and pin maintenance. |
.github/workflows/*.lock.yml |
Embeds v0.5.2 Linux digests in generated workflows. |
.changeset/pin-threat-detect-release-digests.md |
Records the patch release change. |
|
@copilot Please refresh this branch and continue the remaining implementation/review follow-up. Run the pr-finisher skill after updating the branch and pushing the next changes.
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
This comment has been minimized.
This comment has been minimized.
|
@copilot This PR still needs forward progress before a maintainer can merge it. Please address the unresolved review feedback and then run the Unresolved review follow-ups:
I also requested a branch refresh for this PR. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
The cited findings are already addressed in 234ae94; the refreshed branch is ca03807. I completed the requested PR-finisher validation pass (
Refreshed the branch with |
|
@copilot This PR still needs forward progress before a maintainer can merge it. Please address the unresolved Copilot review feedback, refresh the branch if needed, and then run the Relevant review overview: #61857 (review) Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
|
@copilot this PR has merge conflicts. Please run Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
…detect-digests # Conflicts: # .github/workflows/daily-go-test-parallelizer.lock.yml # .github/workflows/daily-reliability-review.lock.yml Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Resolved in
Resolved in |
|
Please address the remaining review feedback below, refresh the branch if needed, and then run the Open review follow-ups (newest first):
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
…detect-digests Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Branch refreshed: merged current The two listed review threads remain satisfied by
Validation after the merge: |
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
|
@davidslater need a procedure/script/skill to upgrade to a newer release of threat detection |
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
|
Please address the remaining review feedback below, refresh the branch if needed, and then run the Open review follow-ups (newest first):
Maintainer note to address as part of the next update: Run: https://github.com/github/gh-aw/actions/runs/35772888314
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed in |
|
🎉 This pull request is included in a new release. Release: |


threat-detectbinaries were verified against a checksum downloaded from the same release, leaving no independent trust root. Compiled workflows now carry reviewed release and digest pins directly.threat-detectv0.5.2 and its complete release digest matrix.checksums.txtdownloads.artifact-base-urlconfiguration.<artifact-base-url>/<version>/threat-detect-linux-{amd64,arm64}layout, runner accessibility, unauthenticated access requirement, byte identity, and pin-update process.Fixes #61855
Fixes #57792